API testing

Refresh an expired access token

Hard120 pts~45 min
  • Token expiry
  • Refresh tokens
Practice app · Acme REST API

A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.

BASE_URL
/api/practice
Console app
/lab/api-testing-refresh-an-expired-access-token

Your starter code already declares BASE_URL — call the API relative to it.

Objective

Let an access token expire, detect TOKEN_EXPIRED, refresh it and retry successfully.

Your task

  1. 1POST BASE_URL + "/auth/token?ttl=1" with the admin fixture; keep access_token and refresh_token.
  2. 2Wait ~2 s, GET BASE_URL + "/auth/me" → assert 401 and error.code "TOKEN_EXPIRED".
  3. 3POST BASE_URL + "/auth/refresh" with { "refresh_token" } → assert 200 and a new access_token.
  4. 4Retry /auth/me with the new token → assert 200.

Acceptance criteria

  • GET /auth/me returns 401 with the expired token
  • POST /auth/refresh returns 200
  • GET /auth/me returns 200 after refresh
  • At least 3 assertions pass

Fixtures

apiKey
tqa_live_key_123
basicUser
admin
basicPassword
secret
username
qa@target.dev
password
Test@123

API testing · API Testing · Authentication